GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,179
Erlang
31
GitHub Actions
19
Go
1,982
Maven
5,000+
npm
3,701
NuGet
656
pip
3,323
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
6,132 advisories
Filter by severity
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus...
High
Unreviewed
CVE-2024-20536
was published
Nov 6, 2024
SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote...
High
Unreviewed
CVE-2024-51326
was published
Nov 4, 2024
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
High
Unreviewed
CVE-2024-24096
was published
Feb 27, 2024
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to...
High
Unreviewed
CVE-2024-9459
was published
Nov 5, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter...
High
Unreviewed
CVE-2024-33147
was published
May 7, 2024
The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab...
High
Unreviewed
CVE-2024-47189
was published
Oct 21, 2024
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4...
High
Unreviewed
CVE-2024-48733
was published
Oct 30, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
High
Unreviewed
CVE-2024-35083
was published
May 23, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-51672
was published
Nov 4, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-51626
was published
Nov 4, 2024
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in...
High
Unreviewed
CVE-2024-48878
was published
Nov 4, 2024
Zohocorp ManageEngine ADAudit Plus versions 8121 and prior are vulnerable to SQL Injection in...
High
Unreviewed
CVE-2024-36485
was published
Nov 4, 2024
SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain...
High
Unreviewed
CVE-2024-25325
was published
Mar 12, 2024
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete...
High
Unreviewed
CVE-2024-48177
was published
Oct 28, 2024
By sending a specially crafted push message, a remote server could have hung the parent process,...
High
Unreviewed
CVE-2024-10466
was published
Oct 29, 2024
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time...
High
Unreviewed
CVE-2024-4902
was published
Jun 7, 2024
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now...
High
Unreviewed
CVE-2024-8924
was published
Oct 29, 2024
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows...
High
Unreviewed
CVE-2024-48427
was published
Oct 24, 2024
Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object...
High
Unreviewed
CVE-2024-50408
was published
Oct 28, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-50465
was published
Oct 28, 2024
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions...
High
Unreviewed
CVE-2024-9987
was published
Oct 22, 2024
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110...
High
Unreviewed
CVE-2024-30157
was published
Oct 21, 2024
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using...
High
Unreviewed
CVE-2024-8625
was published
Oct 21, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-49691
was published
Oct 24, 2024
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the...
High
Unreviewed
CVE-2024-5608
was published
Oct 24, 2024
ProTip!
Advisories are also available from the
GraphQL API